发现 Lighthouse 中存在一个漏洞。远程攻击者通过入侵 spoke 集群,可以利用该漏洞:其漏洞在于,资源注入的目标命名空间来源于对 broker 对象上由攻击者控制的标签或注解的解析。这使得攻击者能够向对等集群中的任意命名空间(包括 kube-system 和 openshift-* 等关键系统命名空间)注入恶意的 EndpointSlices 和 ServiceImports。此漏洞可能导致集群内的权限提升或其他形式的系统被入侵。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Red Hat | Red Hat Advanced Cluster Management for Kubernetes 2 | any |
affected |
any |
affected | ||
any |
affected | ||
any |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Advanced Cluster Management for Kubernetes 2 | - |
cpe:/a:redhat:acm:2
|
|
| Red Hat | Red Hat Advanced Cluster Management for Kubernetes 2 | - |
cpe:/a:redhat:acm:2
|
|
| Red Hat | Red Hat Advanced Cluster Management for Kubernetes 2 | - |
cpe:/a:redhat:acm:2
|
|
| Red Hat | Red Hat Advanced Cluster Management for Kubernetes 2 | - |
cpe:/a:redhat:acm:2
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-67567 | 9.9 CRITICAL | Multicloud-operators-subscription: multicloud-operators-subscription: helmrelease chart ap |
| CVE-2026-66785 | 9.9 CRITICAL | Submariner: submariner: unvalidated endpoint.spec.subnets propagated into wireguard allowe |
| CVE-2026-11861 | 9.6 CRITICAL | Freeipa: idm: ipa: freeipa: obtaining tgs with impersonating cname through trust relations |
| CVE-2026-13097 | 9.1 CRITICAL | Ipa: privilege escalation via krbcanonicalname manipulation due to realm-unaware uniquenes |
| CVE-2026-66787 | 8.7 HIGH | Lighthouse: lighthouse: cross-cluster dns spoofing via unvalidated endpointslice and servi |
| CVE-2026-77176 | 8.1 HIGH | Kata-containers: insufficient validation of createcontainer mount and storage rules in gen |
| CVE-2026-18917 | 7.8 HIGH | Libvirt: integer overflow in nodegetfreepages rpc handler leading to heap buffer overflow |
| CVE-2026-19582 | 7.8 HIGH | Binutils: stack buffer overflow in gnu binutils in rsrc_print_name from an untrusted pe fi |
| CVE-2026-73137 | 7.7 HIGH | Multicloud-operators-subscription: multicloud-operators-subscription: cross-namespace secr |
| CVE-2026-73198 | 7.5 HIGH | Ipa: freeipa: unauthenticated dos in `/ipa/i18n_messages` via unbounded request body read |
| CVE-2026-73197 | 7.5 HIGH | Ipa: freeipa: unauthenticated dos in `/ipa/migration/migration.py` via unbounded request b |
| CVE-2026-19611 | 7.4 HIGH | Wildfly-elytron: org.wildfly.security/wildfly-elytron-password-impl: wildfly-elytron: pass |
| CVE-2026-73199 | 6.5 MEDIUM | Ipa: freeipa: null pointer dereference in `ipa-enrollment` extended operation (`join_oid`) |
| CVE-2026-77014 | 5.3 MEDIUM | Libsoup: libsoup: integer truncation in sort_ranges() comparator causes silent omission of |
| CVE-2026-73196 | 4.3 MEDIUM | Ipa: freeipa: authenticated dos in `otptoken-add` via unbounded otp key decoding/re-encodi |
No comments yet